Skip to main content

4. Server Reply Source Address Selection

Almost all (if not all) DNS clients expect the address from which they receive a response to be the same as the address to which they sent the query which elicited the response. This is true whether the client is a server acting as a client for the purpose of recursive query resolution, or a simple resolver client. The address, along with the identifier (ID) in the response, is used to disambiguate the response, and to filter out fake responses. Whether this was intended when the DNS was designed is not known, but it is now a fact.

Some multi-homed hosts running DNS servers generate replies using a source address which is not the same as the destination address of the client's request packet. Such replies are discarded by the client, as the source address of the reply does not match the source address of the host to which the client sent the original request. That is, it appears to be an unsolicited response.

4.1. UDP Source Address Selection​

To avoid these problems, theIP address in the IP header of the reply must be the address in the destination address field of the IP header of the packet containing the query that caused the reply for UDP. That is, when the server is generating a reply to a query that arrived via UDP, the server must set the source address of the IP header of the reply to the address that was in the destination address field of the IP header of the packet containing the query that caused the reply. This is the only case where the address used as the source of a reply may be different from the address used as the source of the query (or request). Note that the address used as the source of the reply is the same as the address used as the destination of the query, and so is not a "spoofed" address.

For TCP, the address used as the source of the reply is always the same as the address used as the destination of the query, and the port number used as the source of the reply is always the same as the port number used as the destination of the query. This is inherent in the TCP protocol.

For UDP, the source address of the reply must be the destination address of the query, and the source port of the reply must be the destination port of the query. The reply must be sent from the port to which it is directed, except in the case of a server which is using a different port for security or other reasons.

4.2. Port Number Selection​

All replies to queries must be directed to the port from which the query was sent. If the query was received via TCP, this is inherent in the transport protocol. For queries received via UDP, the server must take note of the source port, and use that as the destination port of the reply. The reply should always be sent from the port to which it is directed, except in the special case of a server using a different port for security or other reasons. This will usually be the well-known port assigned to DNS queries [RFC1700].